
violin
Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

A Python package to download Zone Files from the Centralized Zone Data Service hosted by ICAAN.

A tool to quickly do keyword searches over Gitlab and Github for OSINT & bug bounty recon

A Python script to parse net blocks & domain names from SPF record

A script to extract domain names from Content Security Policy(CSP) headers

The repository that contains the algorithms for generating domain names, dictionaries of malicious domain names. Developed to research the…

A TUI bluetooth utility for radar analysis and war driving 🦉

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

Passive Device Tracker (Android)TrackEm Mobile is a real-time, passive Wi-Fi + Bluetooth LE probe-request scanner designed for OSINT, red-team ops,…


An S3 account ID enumeration and bucket discovery tool

LinkedIn enumeration tool to extract valid employee names from an organization through search engine scraping

PowerMeta searches for publicly available files hosted on various websites for a particular domain by using specially crafted Google, and Bing…

Simple, but smart, multi-threaded web crawler for randomly gathering huge lists of unique domain names.

Just a silly recon tool that uses data from SSL Certificates to find potential host names

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)